Agentic DevSecOps Engineer

Fynd

Full TimeNot specifiedPosted 18 days ago

Let the right jobs find you

Get personalised suggestions from verified company career pages, matched to your role, location, level, and skills.

Overview

Position Type

Full Time

Experience

Not specified

Job Description

Role Overview

Fynd operates an AI-native security function. The function builds and operates its own controls — security gates within CI/CD, cloud-posture and attack-surface tooling, detection pipelines, and agentic systems that identify, validate, and prioritise risk across a multi-cloud estate. The mandate extends, through automation, into product security, privacy engineering, security enablement, and resilience. The role holder will own such controls end to end, applying AI tooling as the primary force multiplier.

Candidates are not expected to hold prior expertise in every area listed below. Candidates are expected to demonstrate the capacity to close knowledge gaps rapidly and independently through the disciplined use of AI tooling: specifying the work, building it, verifying it, and owning the outcome.

Responsibilities

  • Own the security stages of the CI/CD estate (Jenkins, Azure DevOps, GitHub Actions), including SAST, SCA, and secrets detection, such that Critical and High severity findings are prevented from reaching production without impeding release velocity.
  • Reduce false positives through custom validation, thereby maintaining engineering confidence in security gates.
  • Secure the software supply chain, including SBOM generation, dependency and base-image provenance, and the governance of secrets and non-human identities across pipelines.
  • Harden self-managed Kubernetes clusters across multiple clouds: RBAC, admission control, network policy, node and operating-system hardening, and managed-image patching pipelines.
  • Build and operate cloud security posture and external attack-surface tooling on GCP, encompassing IAM, organisational policy, and service-account hygiene, together with automated remediation of identified misconfigurations.
  • Engineer detection-as-code upon the existing observability stack (Prometheus, Grafana, ELK), including eBPF-based runtime security.
  • Participate in the security on-call rotation and contribute to incident triage, containment, and post-incident review.
  • Engineer the vulnerability pipeline: a single consolidated queue enriched with reachability and exploitability context, governed by severity-based SLAs, and operating on the principle of find → validate → prioritise → hand over to engineering.
  • Design and build agentic security systems: LLM tool calling and MCP, structured outputs, evaluation harnesses that verify agent output, and deterministic-first architecture with bounded LLM judgement and human override.
  • Secure AI systems in production, including prompt-injection resistance, tool-permission scoping, MCP server security, and threat modelling aligned to the OWASP LLM Top 10 and emerging agentic threat taxonomies.
  • Engineer automated threat modelling and secure design review: threat models generated and maintained from design documents, API specifications, and infrastructure-as-code, with human review reserved for high-risk changes.
  • Define and enforce API security standards as code: specification linting, authentication and authorisation conformance checks, and continuous discovery of undocumented or unauthenticated endpoints.
  • Build continuous multi-tenant isolation assurance: automated cross-tenant access probes executed against production-representative environments, with regressions treated as release-blocking defects.
  • Integrate mobile application security testing into the build pipeline for released applications.
  • Engineer the vetting pipeline for third-party extensions and marketplace submissions: automated static and dynamic screening, credential and secret detection, and permission review prior to listing.
  • Build automated data discovery and classification across datastores and pipelines, maintaining a continuously refreshed map of personal data and its flows.
  • Enforce privacy controls as code: detection of personal data in logs and analytics, retention and deletion enforcement, and encryption and key-management posture checks.
  • Automate the fulfilment of data-principal requests (access, correction, erasure) and the supporting evidence trail, aligned to the Digital Personal Data Protection Act and applicable frameworks.
  • Build behaviour-driven, personalised security training: modules generated and assigned from observed events — a committed secret, a policy breach, a phishing simulation failure — targeted to the individual, their role, and the systems they touch.
  • Measure enablement by behaviour change (repeat-incident rate, time to remediate), not by completion rates.
  • Automate backup assurance: scheduled restore testing with integrity verification, on the principle that an unverified restore is not a backup.
  • Engineer disaster-recovery validation: automated failover exercises and game days measured against defined RTOs and RPOs.
  • Practise chaos engineering across Kubernetes workloads and critical dependencies: controlled fault injection to verify graceful degradation under failure.
  • Practise security chaos engineering: controlled injection of security failures — a disabled control, a dropped admission webhook, a simulated credential exposure — to verify that detection and response operate as designed.
  • Validate detections continuously through automated adversary emulation.
  • Automate the collection of continuous control evidence (ISO 27001, CIS Benchmarks) in support of ongoing audit readiness.

Qualifications

Preferred

  • eBPF runtime security tooling (Falco, Tetragon); distributed tracing and APM applied as security evidence.
  • Chaos engineering tooling (Chaos Mesh, LitmusChaos) and adversary emulation frameworks (Atomic Red Team, Caldera, or equivalent).
  • Exposure to privacy engineering under the Digital Personal Data Protection Act or the GDPR.
  • Mobile application security testing tooling.
  • Working literacy in Kafka, MongoDB, and MySQL; Ansible.
  • GCP Professional Cloud Security Engineer; Certified Kubernetes Security Specialist (CKS).
  • Bug bounty or CTF background.

Required Skills

Ci CdSastScaSecret DetectionE BpfKubernetesGcpAws IamPrometheusGrafanaElkChaos EngineeringAdversary EmulationPrivacy EngineeringStatic Application Security Testing

About the Company

Fynd

Mumbai, India

Share This Job